Managed XDR

5a56p2v08d52.eml (CloudEyE, Remcos) — malware analysis report

File info

Filename
5a56p2v08d52.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
1.1 MB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
dadfe983bb9a56b2b5e0a0c5c29a6543bffa6ac6
SHA256
23161e4226f64f89ab4615ad071e7a9c3979e321214d7977a9cd34ee1bffebd4
MD5
e870ed930f89aee18b0a5cc140492dd4

Malwares

  • CloudEyE
  • Remcos

Signatures

Execution

T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks
T1059 nsis_suspicious_filenames: Nsis contains files with suspicious names

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1055.012 injection_runpe: Injects code into another process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1045 guloader_behaviour2: Cloudeye/GuLoader specific behaviour has been detected
T1055.012 injection_runpe: Injects code into another process
T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 guloader_behaviour: Cloudeye/GuLoader specific behaviour has been detected
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1562 dep_disable: Disables DEP
T1564.001 stealth_file: Creates hidden or system files
T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 nsis_archive: One of the packages is NSIS archive
T1027.002 nsis_suspicious_filenames: Nsis contains files with suspicious names
T1497.001 antivm_queries_computername: Retrieves the computer name

Discovery

T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1497.001 antivm_queries_computername: Retrieves the computer name
T1135 server_share_info: Retrieves information about each shared resource on a server

Command and Control

T1102.003 cloud_google: Connects to cloud services of Google (potentially for malicious payload delivery)
T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

yara_rules: Static rules
ce_info: Remcos Configuration Data found
copies_self: Creates a copy of itself
executes_dropped_exe: Executes dropped exe files
unnamed_region_exception_handler: Creates an exception handler in an unnamed region
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
net_dumps_in_native: .Net dumps have been found in native PE
creates_suspended_process: Creates suspended process
creates_exe: Creates executable files in the file system
creates_in_programdata: Creates files in the ProgramData directory
checktokenmembership: Checks user token with CheckTokenMembership call
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay

Related reports